Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-27611


Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology Audio Station before 6.5.4-3367 allows remote authenticated users to delete arbitrary files via unspecified vectors.


Published

2022-07-28T08:15:08.667

Last Modified

2024-11-21T06:56:01.343

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application synology audio_station < 6.5.4-3367 Yes

References